LIVE FEED
Subscribe
//

Category: Vulnerabilities

Vulnerabilities OnTrac Discloses Data Breach After Network Intrusion
MEDIUM Vulnerabilities

OnTrac Discloses Data Breach After Network Intrusion

The last-mile delivery firm says an attacker accessed files over a three-day span in March, and its response language hints at a…

by Robbie · 3 weeks ago
Vulnerabilities NodeBB Patches Eight High-Severity Flaws Found by AI Pentest Agents
HIGH Vulnerabilities

NodeBB Patches Eight High-Severity Flaws Found by AI Pentest Agents

Aikido Security says its AI-driven code review uncovered eight high-severity vulnerabilities in the NodeBB forum platform in just six hours, exposing admin…

by Robbie · 3 weeks ago
Vulnerabilities RefluXFS: Nine-Year-Old Linux Kernel Flaw Grants Root via XFS Race Condition
HIGH Vulnerabilities

RefluXFS: Nine-Year-Old Linux Kernel Flaw Grants Root via XFS Race Condition

A race condition in the XFS filesystem's reflink copy-on-write path, present since kernel 4.11, lets unprivileged local users overwrite root-owned files and…

by Robbie · 3 weeks ago
Vulnerabilities Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale
CRITICAL Vulnerabilities

Russian APT ‘Laundry Bear’ Exploited Zimbra Zero-Day to Steal Email at Scale

A joint advisory from CISA, NSA, FBI and international partners details a Russian state-supported campaign that used a zero-click Zimbra Collaboration Suite…

by Robbie · 3 weeks ago
Vulnerabilities Stadler Rail Refuses $12.3M Everest Ransom After Supplier Data Breach
MEDIUM Vulnerabilities

Stadler Rail Refuses $12.3M Everest Ransom After Supplier Data Breach

Swiss rail manufacturer Stadler says a breach at a third-party file-sharing platform exposed technical supplier documents, but the company is refusing Everest's…

by Robbie · 3 weeks ago
Vulnerabilities Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline
CRITICAL Vulnerabilities

Check Point Zero-Day Under Active Attack, CISA Sets July 25 Deadline

A critical authentication bypass in Check Point's Security Management and Multi-Domain Management products is being exploited against internet-exposed environments, prompting an emergency…

by Robbie · 3 weeks ago
Vulnerabilities House Defense Bill Passes With Decade-Long Extension of CISA 2015 Info-Sharing Law
Vulnerabilities

House Defense Bill Passes With Decade-Long Extension of CISA 2015 Info-Sharing Law

The House approved its version of the 2027 NDAA, which includes a provision to reauthorize the 2015 Cybersecurity Information Sharing Act for…

by Robbie · 3 weeks ago
Vulnerabilities Attackers Mass-Exploit wp2shell WordPress Flaws to Plant Webshells
CRITICAL Vulnerabilities

Attackers Mass-Exploit wp2shell WordPress Flaws to Plant Webshells

Threat actors are chaining two critical WordPress Core vulnerabilities dubbed wp2shell to deploy PHP webshells, install malicious plugins, and harvest credentials on…

by Robbie · 3 weeks ago
Vulnerabilities Critical SharePoint RCE Flaw Under Active Exploitation, Attackers Stealing Machine Keys
CRITICAL Vulnerabilities

Critical SharePoint RCE Flaw Under Active Exploitation, Attackers Stealing Machine Keys

Hackers began exploiting CVE-2026-50522 within hours of a public PoC release, stealing SharePoint machine keys to maintain persistent access even after servers…

by Robbie · 3 weeks ago
Vulnerabilities ServiceNow Sandbox Escape Bug Exploited Days After Patch, Details Disputed
CRITICAL Vulnerabilities

ServiceNow Sandbox Escape Bug Exploited Days After Patch, Details Disputed

A critical unauthenticated remote code execution flaw in ServiceNow's AI platform, patched on July 14, is reportedly under active exploitation, though the…

by Robbie · 3 weeks ago
Vulnerabilities Microsoft Issues Manual Fix for WSUS Sync Delays and Timeouts
MEDIUM Vulnerabilities

Microsoft Issues Manual Fix for WSUS Sync Delays and Timeouts

A metadata buildup issue was causing Windows Update scans to fail or time out on WSUS servers. Microsoft has now published manual…

by Robbie · 3 weeks ago
Vulnerabilities Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation
CRITICAL Vulnerabilities

Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation

Threat intelligence firm Defused says attackers are exploiting a critical unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform, days after patches were…

by Robbie · 4 weeks ago
1 3 4 5 13

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.